dhi.io/gitea
1, 1-debian, 1-debian13, 1.27, 1.27-debian, 1.27-debian13, 1.27.3, 1.27.3-debian, 1.27.3-debian13
sha256:8fc181cf7d648ffdb30db3619859d904a4ae6a2058a03b1a10e233a351145adb
Manifest digest:sha256:f7d941b2f3d82be3d69f0358658a41700d9385e941584605394d12084cdd74e4
Size
84.14 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitea:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitea:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitea@sha256:908c98e7f78bd7948ac400227369215668e6d31483734315161cf099d78d4f69 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitea@sha256:19136481cb072ecb0ff97375f53d2346981499394268dc82191680d351534be3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitea@sha256:18a0dd91b33b5b81b0ec4812fd0b0c7e49fe10aac91478dcbb1e8a92a10103a3 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitea@sha256:abba2c00187153ca0ee7cf929f2e31acda96443e47ca63a179e6830964029833 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitea@sha256:430e594a54dacff20d4bddfd2e32a428d0febe595609079323abbd67a797dcc1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitea@sha256:f127a47fda4c0819f8447d4d0676f68383442c595808b966f788afc62710c0ed |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitea@sha256:cf429c5bc8180f0950232bd6af1ea0b74c94d61f821ab6f6164c24d726e88153 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitea@sha256:3c7b6b5fa96cacef8f30fd2a173e0a23db4feedc41b5033f67dedd100eebae76 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitea@sha256:b27f6a75554d4c54741bd73c5ccd090807a7e09254e8801f0869dc8169c8b6fe |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitea@sha256:3889092bec23d991be0657b17d9656ef719e477a6fd728ca6a67701d7cfe812a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitea@sha256:09a45d927bcc142fab45347cbcd9f1bba532cb4eb08a1d71d13e069003a3adba |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitea@sha256:01f5a72f33b25111aefdda557379607af7fbe97af817cc0dd2f6f76c091c339e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitea@sha256:e17125458f77fb65a1923d39a030ac82e30f6f514cc56365c1566eef398b7243 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitea@sha256:10acb5aafcec1f908a41a52a63ab0c78a5a14b63bfd9aeb5d52fd49a04b06b2b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitea@sha256:fa01df11d7d1e879096070bd4bf504c3272f7c70a658a0e8a2617bc1aafa416b |